PT-2025-38069 · Unknown · Kubernetes Client
Elliott-Beach
·
Published
2025-09-15
·
Updated
2025-09-23
·
CVE-2025-9708
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Kubernetes C# client versions prior to 17.0.14
Description
A flaw exists in the Kubernetes C# client's certificate validation logic, allowing it to accept certificates from any Certificate Authority (CA) without proper trust chain verification. This can enable a malicious actor to present a forged certificate, potentially intercepting or manipulating communication with the Kubernetes API server, leading to man-in-the-middle attacks and API impersonation.
Recommendations
Kubernetes C# client versions prior to 17.0.14 should be updated to version 17.0.14 or later.
As an alternative, move the CA certificates into the system trust store instead of specifying them in the kubeconfig file.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubernetes Client